THREAT OPS › Threat News › [NVD] CVE-2026-77704 (LOW 2.7) — The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not check that a user holds the required capability before letting them change an appointment's status, allowing customers to set arbitrary statuses on appointments they are booked on, including
[NVD] CVE-2026-77704 (LOW 2.7) — The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not check that a user holds the required capability before letting them change an appointment's status, allowing customers to set arbitrary statuses on appointments they are booked on, including
CVE-2026-77704 CVSS: 2.7 LOW Published: 2026-08-29T06:17:44.150
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not check that a user holds the required capability before letting them change an appointment's status, allowing customers to set arbitrary statuses on appointments they are booked on, including approving their own bookings that were left awaiting ap
Indicators of compromise
- CVE-2026-77704cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-77704